This is an inherent flaw in the system though, right? Not anything new.

Not quite. This makes ACH more accessible than it was before, which makes it that much easier to commit ACH fraud. Also, it is possible to layer a secure layer on top of ACH, but Dwolla didn't do that. They either chose not to, or they don't know how. They just exposed the ACH functionality directly.

